Cross-site scripting in Google Chromium - CVE-2026-87632
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in SanitizerAPI when processing crafted web content. A remote attacker can cause a victim to process crafted web content to execute arbitrary script in a victim's browser.
User interaction is required.
Affected software
Google Chrome
How to mitigate CVE-2026-87632
Google Chrome - update to 153.0.8010.36